Privacy
Privacy Policy
AIMTRACER is built around public CS2 account lookup data. This page explains what is requested, displayed, and cached when you use the website or Chrome extension, the legal basis we rely on, how long anything is kept, and the rights you have over data about you — including the right to have your profile removed from the service.
Who is responsible for this data
AIMTRACER (“AIMTRACER”, “we”) is an independently operated project, and is the controller for the processing described on this page. It is not affiliated with Valve, FACEIT, or Leetify.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy questions and requests go to [email protected].
What AIMTRACER is, and what it is not
AIMTRACER is a lookup tool. It reads data that Steam, FACEIT, and Leetify already publish about an account, presents it on one page, and derives a small number of statistics from it. It does not host a database of players: each lookup is performed live, on request, for the account you searched for.
AIMTRACER is not an anti-cheat service, does not determine whether anyone has cheated, is not affiliated with Valve, FACEIT, or Leetify, and has no ability to ban, restrict, or report any account. Nothing shown on the site is a finding of wrongdoing.
What we do not do
Some of what follows is assumed about lookup sites often enough that it is worth stating plainly. AIMTRACER does not:
- sell, licence, rent, or trade personal data, or share it with data brokers or advertisers;
- run advertising networks, ad profiling, retargeting, fingerprinting, or cross-site tracking of any kind — the only third-party analytics is Google Analytics, and only if you accept it;
- store the profiles it displays, or build a standing database, dossier, or history of any player looked up;
- bypass, circumvent, or work around privacy settings — if something is private on Steam, FACEIT, or Leetify, it is not visible here either;
- report, flag, or escalate anyone to Valve, FACEIT, Leetify, tournament organisers, or anti-cheat operators, and it has no technical ability to ban or restrict any account;
- score, rank, rate, or grade players, or publish a blacklist, a “cheater list”, or a leaderboard — AIMTRACER shows the figures its sources publish and draws no conclusion of its own from them;
- send unsolicited marketing, or use lookup data to contact anyone.
Your own settings control what appears here
AIMTRACER can only show what the source services publish about your account, and it reads their visibility flags rather than working around them. Setting your Steam profile, game details, or inventory to private, or restricting your FACEIT or Leetify visibility, removes that data from AIMTRACER automatically — the next lookup simply shows it as private.
This is usually faster and more complete than asking us, because it also affects every other site that reads the same public interfaces. If you want your profile withheld from AIMTRACER specifically, or you want it withheld while remaining public elsewhere, use the request route below and we will suppress it.
Data we process
When you search, AIMTRACER may request and display:
- public Steam profile data — Steam64 ID, vanity URL, persona name, avatar, account age, online status, CS2 playtime, public ban flags;
- public FACEIT data — nickname, ELO, level, win rate, recent matches;
- public Leetify data — aim, utility, positioning, clutch, reaction time, K/D, and match summaries;
- public Steam inventory metadata and public market-price estimates;
If a profile or inventory is private, hidden, or unavailable, the site shows limited data instead. AIMTRACER cannot see anything that the source service does not already make public.
Where the data comes from
Most of the data above is not collected from you. It is obtained from the public interfaces of Steam, FACEIT, and Leetify, which means Article 14 GDPR applies: this page is the notice describing that processing.
We do not contact each account individually, because a lookup service holds no standing list of people to notify and no contact details for them — an individual notice would require collecting far more personal data than the lookup itself uses. We therefore rely on Article 14(5)(b) and publish this notice, keep it linked from every page, and honour objections and erasure requests as described below.
Legal basis
For public lookup data we rely on our legitimate interests under Article 6(1)(f) GDPR: letting players vet potential teammates and opponents, making already-public competitive data readable in one place, and operating and securing the service.
We have weighed those interests against the interests and rights of the people looked up. The factors we consider material are that the data is already published by the source services and remains under the account holder’s own privacy controls; that it concerns an in-game persona rather than identity documents, contact details, or location; that no special category data is involved; and that the processing is transient rather than a permanent profile. Where those factors do not hold for a particular person — for example a private individual who does not want a public performance page at all — the balance can fall the other way, which is why the objection route below exists and why we act on it.
For accounts, logins, and clips we rely on Article 6(1)(b) — performance of the service you signed up for. For security, abuse prevention, and rate limiting we rely on Article 6(1)(f).
Accounts, sign-in and clips
Signing in is optional and uses Steam OpenID. We never see or receive your Steam password: Steam authenticates you and returns your Steam64 ID to us. For a signed-in account we hold your Steam64 ID, display name, avatar URL, account status, and a session token stored in a cookie so you stay logged in.
If you use the clip features, we additionally store the clips you create and their associated metadata — map, round, kills, headshots, clip type, duration, match date, demo name, and per-kill events — together with any clips you mark as favourites. Clips you share are reachable by anyone holding the share link.
Account and clip data is kept while your account exists. You can ask us to delete your account and clips at any time using the contact address above.
Chrome extension
The AIMTRACER Chrome extension runs on Steam Community profile pages. It reads the current Steam profile page URL and displays an AIMTRACER stats panel on that page. To load the panel, the extension sends the Steam profile URL to AIMTRACER’s public player lookup API — the same API the website uses, and subject to the same suppression list.
The extension does not collect passwords, cookies, private messages, payment information, browser history, or unrelated page content. It may save a small preference in Chrome storage, such as whether the panel opens or stays collapsed by default; that setting stays in your browser.
Caching, retention and logs
Lookup results are held in server memory only, to keep searches fast and reduce load on the source services. Profile responses are reused for about a minute and may be served as stale data for up to ten minutes; inventory values and medals are reused for about ten minutes and may be served as stale data for up to twenty-four hours. These caches are not a database: they hold a bounded number of recent entries, are evicted as newer lookups arrive, and are lost entirely whenever the server restarts or the site is redeployed.
Our own application logs record which endpoint was called, how it went, how long it took, and the caller’s IP address. They do not record the Steam account that was looked up, and they are not sent to any third-party log service.
Separately, our hosting provider keeps ordinary access logs — the requested URL, IP address, browser metadata, timestamps, and error details — under its own short retention period. Because a profile page is addressed as /player/<SteamID>, that identifier appears in those URLs; this is unavoidable for any site with addressable pages, and the same is true of your own browser history. These logs exist to keep the service running and to investigate abuse. They are not used to build profiles of individuals, are never combined with lookup data, and expire on the provider’s schedule without us acting on them.
Analytics
AIMTRACER uses Google Analytics to understand general site usage, such as page views, searches, successful and failed lookups, and clicks on help or shortcut elements. These events are used to improve the site.
Analytics runs only if you accept it. Until you choose, no Google Analytics script is loaded and no analytics cookie is set — declining leaves the site fully usable. Your choice is remembered in your browser’s local storage under aimtracer:analytics-consent and never leaves your device; clearing your site data resets it and you will be asked again. This is the consent we rely on for analytics under Article 6(1)(a) GDPR and the ePrivacy rules, and you can withdraw it at any time by clearing that stored choice and declining.
Analytics events do not include Steam IDs, player names, Steam profile URLs, API keys, passwords, third-party account cookies, private messages, or payment information. Google processes analytics data as an independent controller under its own privacy policy.
Who else receives the data
We do not sell personal data, do not share it with data brokers, and do not use it for unsolicited marketing. Data is handled by our hosting and infrastructure providers acting as processors on our instructions, and by Google Analytics as described above.
Steam, FACEIT, Leetify, and market-price providers are our sources, not recipients: we request already-public data from them, we do not send them information about the people you look up beyond the identifier needed to retrieve that public data. They control their own data, privacy settings, API availability, and deletion processes, and they act as separate controllers. To change source data, update your privacy or account settings directly on those services — a change there is the only thing that can remove the data at its origin.
Where one of these providers processes data outside the EEA, that transfer relies on the provider’s own safeguards under Chapter V GDPR, typically an adequacy decision or the Standard Contractual Clauses.
Data we do not want
AIMTRACER does not knowingly process special category data under Article 9 GDPR — health, biometrics, political opinions, religion, sexual orientation, trade union membership, or ethnic origin. If a persona name, avatar, or profile summary happens to reveal something of that kind, it is displayed only because the source service already publishes it, and it is not indexed, analysed, or used in any score.
The service is not directed at children under 16 and we do not knowingly create accounts for them.
Your rights
Under the GDPR and UK GDPR you have the right to:
- access the personal data we process about you (Article 15);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17);
- restrict processing while a dispute is resolved (Article 18);
- object to processing based on legitimate interests, including the public lookup (Article 21);
- receive account data you provided in a portable format (Article 20, where applicable);
- lodge a complaint with a supervisory authority (Article 77).
Exercising these rights is free. We do not degrade or restrict anyone’s use of the service for having made a request.
How to make a request
Email [email protected] and state which right you are exercising and which Steam account it concerns. We respond within one month of receiving the request, and will tell you within that month if the request’s complexity means we need the extension permitted by Article 12(3).
Because a request about a Steam account is a request about someone else’s public profile unless it comes from the account holder, we verify control of the account before acting — normally by asking you to sign in once with Steam OpenID, which proves control without disclosing anything to us. We will never ask for your Steam password, and we do not require identity documents for this. If we cannot verify control, we will say so rather than act on an unverified request (Article 12(6)).
We may decline or charge a reasonable fee for requests that are manifestly unfounded or excessive, in particular repetitive ones, and will explain our reasons if we do (Article 12(5)). A request that is generated in bulk, or that demands things this service does not do, is not for that reason refused — we answer the parts that apply to us and say plainly which parts do not.
Common requests, and how we answer them
These come up often enough that the answers are published here rather than repeated by email. Nothing below limits your rights; it describes what this particular service is able to do.
- “Erase all personal data relating to me.”
- Done by suppression, as described above: the profile page, the lookup API, the extension, and the share-card image all refuse the account, and the URL is set to noindex and dropped from our sitemap. There is no stored profile to delete, because we never had one.
- “Purge your server caches and hosting logs of my data.”
- Lookup caches live in server memory, expire within minutes to at most twenty-four hours, and are lost entirely on every restart and deploy. Once an account is suppressed the cache is bypassed anyway, so no cached copy of it can be served. Our application logs no longer record the Steam account looked up at all, and nothing is sent to a third-party log service. Our hosting provider’s access logs do contain the requested URL, which for a profile page includes the SteamID — no site with addressable pages can avoid that — but they are short-lived, expire on the provider’s schedule, and are never used for profiling. We cannot selectively delete entries inside a provider’s access logs, and we will not claim otherwise.
- “Confirm no Steam IDs were sent to Google Analytics.”
- Analytics events are limited to the interaction types listed above and do not carry Steam IDs, player names, or profile URLs. Analytics also only runs at all for visitors who accepted it.
- “Notify Steam, FACEIT, and Leetify under Article 19.”
- Article 19 concerns recipients to whom a controller has disclosed personal data. These services are our sources, not our recipients: we request already-public data from them and disclose nothing to them beyond the identifier needed to retrieve it. There is accordingly no recipient to notify. If that ever changes, we will notify and say so here.
- “Provide your balancing test, or justify your exemption.”
- Our legitimate interests reasoning is set out in the Legal basis section above rather than held back for disputes. We do not generally invoke the Article 17(3) exemptions against an individual’s erasure or objection: we suppress the account instead.
- “Remove my page from Google.”
- Suppression makes the URL return 404 and marks it noindex, and removes it from our sitemap, which is everything within our control. When search engines drop the result is their decision and their schedule, not ours. You can speed this up with the search engine’s own removal tool, and we will confirm the 404 in writing if that helps your request to them.
- “Correct a statistic that is wrong.”
- We display source figures rather than author them, so a correction has to happen at Steam, FACEIT, or Leetify; the next lookup then reflects it. If the problem is that data is attributed to the wrong account, that is ours to fix — tell us and we will investigate.
- A request about someone else’s account.
- We act only for the account holder, verified as described above. We will not suppress, alter, or disclose a third party’s profile on someone else’s say-so, and we will not confirm whether any particular person has contacted us.
What erasure means here
AIMTRACER does not store the profiles it displays, so erasure is not a matter of deleting a record. When we honour an erasure request or an objection, we add the Steam64 ID and known vanity URLs to a suppression list. From that point the account is refused at every surface — the public profile page returns 404, the lookup API and the Chrome extension refuse the request, share-card images are not generated, and the URL is marked noindex and removed from our sitemap so search engines drop it. The refusal happens before any cache is read and before any request to Steam, FACEIT, or Leetify, so no fresh data about the account is requested and no stale cached copy can be served.
The suppression list itself contains only those identifiers and the date the request was honoured. We keep it under Article 17(3)(b) and Article 17(3)(e): it is the only way to keep the erasure effective, since deleting the identifier would simply let the next lookup rebuild the page from public sources. It is never used for any other purpose. If you later want your profile visible again, tell us and we will remove the entry.
What suppression cannot do is change the source. Your data stays public on Steam, FACEIT, and Leetify until you change your privacy settings there, and we have no ability to erase it on those services or to remove it from other sites that read them.
Security
Traffic is served over HTTPS. Lookup endpoints are rate limited and validate their input. Session cookies are HTTP-only, so page scripts cannot read them. Administrative interfaces require separate authentication. No service is perfectly secure, but we take these measures as required by Article 32 and review them as the service changes.
Complaints
If you are unhappy with how we handled your request, you can complain to your local data protection authority. In Hungary this is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11, naih.hu. In the UK it is the Information Commissioner’s Office, ico.org.uk. You may also complain to the authority where you live or work. We would rather hear from you first, at [email protected].
Changes to this policy
We update this page when the service changes. The date at the bottom shows when it was last revised. Material changes to what we process or why will be reflected here before they take effect.
Last updated September 10, 2026.